Skip to content
Tools / OpenHands / Security

Security Deep Dive

OpenHands

Security posture and CVE patch evidence from tracked releases.

Back to Tool

1 actively-exploited dependency CVE affects cloud-1.47.1.

KEV-listed CVEs are confirmed exploited in the wild — patch urgently.

Versions by Severity

CVEs are attributed to tracked releases published before the patch release.

20 versions tracked
Version Published C H M L KEV Notes
cloud-1.47.1 2026-07-21
Latest
cloud-1.47.0 2026-07-21
cloud-1.46.2 2026-07-15
cloud-1.46.1 2026-07-14
cloud-1.46.0 2026-07-10
cloud-1.45.1 2026-07-09
1.11.0 2026-07-09
cloud-1.45.0 2026-07-09
cloud-1.44.0 2026-07-09
1.10.0 2026-07-08
1.9.3 2026-07-08
1.9.2 2026-07-07
cloud-1.42.0 2026-07-07
1.9.1 2026-07-07
cloud-1.41.0 2026-07-06
1.9.0 2026-07-06
cloud-1.40.0 2026-06-26
cloud-1.39.0 2026-06-24
1.8.0 2026-06-10
Patches CVE-2023-4863 Patches CVE-2026-42208 Patches CVE-2026-42271
1.7.0 2026-05-01 1 2 KEV 3
— Signed — SLSA — SBOM ✗ Security policy Weekly cadence · 0d median Active maintainer

Trust Signals — 2 of 9 Present

Evidence already collected from releases and repository metadata.

2/9 Present
Signed releases Unknown
Latest release artifact signature Latest release
SLSA provenance Unknown
Attestation predicate level Latest release
SBOM published Unknown
GitHub SBOM API Latest release
SECURITY.md Absent
GitHub repository metadata Repository policy
Checked: 11d ago
Release cadence: weekly Present
0d median over recent releases Release history
Latest release: 5d ago
Maintainer active Present
Recent commit activity Repository
Last commit: 8d ago
Checksums (SHA256SUMS) Not active yet
SHA256SUMS or equivalent Release asset
Latest release: 5d ago
GitHub Actions attestation Not active yet
actions/attest-build-provenance Workflow file
Latest release: 5d ago
Signing assets Not active yet
.sig, .crt, cosign.pub, or similar Release asset
Latest release: 5d ago
0.5/10 Security Score
Dependency Exposure 181 transitive dependency CVEs found in the latest SBOM. 21 critical.

Security Score

A composite score aggregating Scorecard performance, CVE patch history, OpenSSF badge tier, and dependency vulnerability exposure. Score ≥ 7.0 is healthy; < 4.0 warrants attention.

epss

0.00 / 0.5

Max EPSS 0.997

freshness

1.00 / 1.0

1d stale

scorecard

2.00 / 4.0

⚠ Estimated — not yet collected

cve health

0.00 / 2.5

No open CVEs

patch speed

0.50 / 0.5

⚠ Estimated — no CVE patch history

kev exposure

-1.50 / 1.5

KEV exposure detected

supply chain risk

-1.50 / 10.0

Risk 100.0/100

Score breakdown

schema v2

Vulnerability posture

vulnerability posture

0.0

25%

direct cves: clear cve scan: available

Release responsiveness

release responsiveness

10.0

5%

patch speed days: no_history

Dependency exposure

dependency exposure

0.0

10%

supply chain risk: 100.0 transitive cves: 21c/98h

Provenance trust

provenance trust

5.0

40%

scorecard score: estimated openssf badge: none

Maintainer health

maintainer health

10.0

10%

activity freshness: 1d

Operational risk

operational risk

0.0

10%

kev exposure: detected epss max: 0.997
How is this calculated?

The six dimensions group the legacy score signals into weighted categories: direct vulnerability status, patch responsiveness, dependency exposure, provenance checks, maintainer activity, and exploitability risk. The flat component values above remain available for compatibility.

Supply Chain Risk

Risk 100.0/100
21 Transitive critical CVEs
1 KEV-transitive CVEs
64% Dependency freshness

OpenSSF Badge

OpenSSF none

Badge indicates adherence to open-source best practices.

CVE Patch History

Tracks CVEs that were addressed in tagged releases. Shorter gap between disclosure and patch = faster response. EPSS = predicted probability of exploitation in next 30 days (FIRST.org); colored at ≥90%ile and ≥50%ile.

CVEs Patched by Year

Critical High Medium Low
2026
3
CVE Severity EPSS Disclosed Fixed in Days to fix vs Ecosystem Median KEV
CVE-2023-4863 HIGH 99%ile 1.8.0 KEV
CVE-2026-42208 CRITICAL 99%ile 1.8.0 KEV
CVE-2026-42271 HIGH 99%ile 1.8.0 KEV

KEV = CISA Known Exploited Vulnerabilities catalog — actively exploited in the wild.

Dependency Vulnerabilities

2908 dependencies scanned View full dependency list →

Scanning the SBOM (Software Bill of Materials) of the latest release for known vulnerabilities in transitive dependencies.

Critical

21

High

98

Medium

53

Low

3

Unknown

6

1 dependency vulnerabilities are in KEV.

CISA confirmed these vulnerabilities are actively exploited. Treat as critical priority.

Critical 21 High 98 Medium 53 Low 3 Unknown 6
CVE Severity KEV Dependency Affected version Cleared in release
CVE-2012-0805 critical sqlalchemy 1.8.0
CVE-2014-3007 critical pillow 1.8.0
CVE-2016-4009 critical pillow 1.8.0
CVE-2019-17626 critical reportlab 1.8.0
CVE-2019-19450 critical reportlab 1.8.0
CVE-2019-6446 critical numpy 1.8.0
CVE-2019-7164 critical sqlalchemy 1.8.0
CVE-2019-7548 critical sqlalchemy 1.8.0
CVE-2020-11538 critical pillow 1.8.0
CVE-2020-13092 critical scikit-learn 1.8.0
CVE-2020-17446 critical asyncpg 1.8.0
CVE-2020-5310 critical pillow 1.8.0
CVE-2020-5311 critical pillow 1.8.0
CVE-2020-5312 critical pillow 1.8.0
CVE-2021-25289 critical pillow 1.8.0
CVE-2021-34552 critical pillow 1.8.0
CVE-2021-41945 critical httpx 1.8.0
CVE-2022-22817 critical pillow 1.8.0
CVE-2023-41419 critical gevent 1.8.0
CVE-2023-50447 critical pillow 1.8.0
CVE-2026-42208 critical litellm 1.83.0 1.9.0
CVE-2014-1858 high numpy 1.8.0
CVE-2014-1859 high numpy 1.8.0
CVE-2014-1932 high pillow 1.8.0
CVE-2014-3589 high pillow 1.8.0
CVE-2014-3598 high pillow 1.8.0
CVE-2014-9601 high pillow 1.8.0
CVE-2016-0775 high pillow 1.8.0
CVE-2016-1516 high opencv-python 1.8.0
CVE-2016-2533 high pillow 1.8.0
CVE-2016-3076 high pillow 1.8.0
CVE-2016-9190 high pillow 1.8.0
CVE-2017-1000450 high opencv-python 1.8.0
CVE-2017-12597 high opencv-python 1.8.0
CVE-2017-12598 high opencv-python 1.8.0
CVE-2017-12599 high opencv-python 1.8.0
CVE-2017-12600 high opencv-python 1.8.0
CVE-2017-12601 high opencv-python 1.8.0
CVE-2017-12602 high opencv-python 1.8.0
CVE-2017-12603 high opencv-python 1.8.0
CVE-2017-12604 high opencv-python 1.8.0
CVE-2017-12605 high opencv-python 1.8.0
CVE-2017-12606 high opencv-python 1.8.0
CVE-2017-12852 high numpy 1.8.0
CVE-2017-12862 high opencv-python 1.8.0
CVE-2017-12863 high opencv-python 1.8.0
CVE-2017-12864 high opencv-python 1.8.0
CVE-2017-18009 high opencv-python 1.8.0
CVE-2019-14491 high opencv-python 1.8.0
CVE-2019-14492 high opencv-python 1.8.0
CVE-2019-14493 high opencv-python 1.8.0
CVE-2019-16865 high pillow 1.8.0
CVE-2019-19911 high pillow 1.8.0
CVE-2019-5063 high opencv-python 1.8.0
CVE-2019-5064 high opencv-python 1.8.0
CVE-2019-9423 high opencv-python 1.8.0
CVE-2020-10177 high pillow 1.8.0
CVE-2020-10378 high pillow 1.8.0
CVE-2020-10379 high pillow 1.8.0
CVE-2020-10994 high pillow 1.8.0
CVE-2020-28463 high reportlab 1.8.0
CVE-2020-28975 high scikit-learn 1.8.0
CVE-2020-35653 high pillow 1.8.0
CVE-2020-35654 high pillow 1.8.0
CVE-2020-5313 high pillow 1.8.0
CVE-2021-23437 high pillow 1.8.0
CVE-2021-25287 high pillow 1.8.0
CVE-2021-25288 high pillow 1.8.0
CVE-2021-25290 high pillow 1.8.0
CVE-2021-25291 high pillow 1.8.0
CVE-2021-25293 high pillow 1.8.0
CVE-2021-27921 high pillow 1.8.0
CVE-2021-27922 high pillow 1.8.0
CVE-2021-27923 high pillow 1.8.0
CVE-2021-28675 high pillow 1.8.0
CVE-2021-28676 high pillow 1.8.0
CVE-2021-28677 high pillow 1.8.0
CVE-2021-41495 high numpy 1.8.0
CVE-2022-24303 high pillow 1.8.0
CVE-2022-30595 high pillow 1.8.0
CVE-2022-45198 high pillow 1.8.0
CVE-2022-45199 high pillow 1.8.0
CVE-2023-33733 high reportlab 1.8.0
CVE-2023-44271 high pillow 1.8.0
CVE-2023-4863 high KEV pillow 1.9.0
CVE-2024-28219 high pillow 1.8.0
CVE-2025-48379 high pillow 1.8.0
CVE-2025-53365 high mcp 1.8.0
CVE-2025-53366 high mcp 1.8.0
CVE-2025-59288 high playwright 1.53.1 1.8.0
CVE-2025-61385 high pg8000 1.8.0
CVE-2025-66416 high mcp 1.8.0
CVE-2025-68429 high storybook 9.0.12 1.8.0
CVE-2026-25990 high pillow 1.8.0
CVE-2026-27148 high storybook 9.0.12 1.8.0
CVE-2026-33079 high mistune 3.2.0 1.8.0
CVE-2026-35397 high jupyter-server 2.17.0 1.8.0
CVE-2026-40110 high jupyter-server 2.17.0 1.8.0
CVE-2026-40171 high jupyterlab 4.5.6 1.8.0
CVE-2026-40171 high notebook 7.5.5 1.8.0
CVE-2026-40192 high pillow 1.8.0
CVE-2026-40934 high jupyter-server 2.17.0 1.8.0
CVE-2026-42033 high axios 1.15.0 1.8.0
CVE-2026-42035 high axios 1.15.0 1.8.0
CVE-2026-42043 high axios 1.15.0 1.8.0
CVE-2026-42203 high litellm 1.83.0 1.8.0
CVE-2026-42215 high gitpython 3.1.46 1.8.0
CVE-2026-42264 high axios 1.15.0 1.8.0
CVE-2026-42266 high jupyterlab 4.5.6 1.8.0
CVE-2026-42271 high litellm 1.83.0 1.9.0
CVE-2026-42284 high gitpython 3.1.46 1.8.0
CVE-2026-42311 high pillow 1.8.0
CVE-2026-42557 high notebook 7.5.5 1.8.0
CVE-2026-42557 high jupyterlab 4.5.6 1.8.0
CVE-2026-42561 high python-multipart 0.0.26 1.8.0
CVE-2026-44243 high gitpython 3.1.46 1.8.0
CVE-2026-44244 high gitpython 3.1.46 1.8.0
CVE-2026-44307 high mako 1.3.10 1.8.0
GHSA-qr4w-53vh-m672 high opencv-python 1.8.0
CVE-2014-1933 medium pillow 1.8.0
CVE-2016-0740 medium pillow 1.8.0
CVE-2016-1517 medium opencv-python 1.8.0
CVE-2016-9189 medium pillow 1.8.0
CVE-2017-14136 medium opencv-python 1.8.0
CVE-2017-17760 medium opencv-python 1.8.0
CVE-2018-5268 medium opencv-python 1.8.0
CVE-2018-5269 medium opencv-python 1.8.0
CVE-2019-15939 medium opencv-python 1.8.0
CVE-2019-16249 medium opencv-python 1.8.0
CVE-2019-19624 medium opencv-python 1.8.0
CVE-2020-35655 medium pillow 1.8.0
CVE-2021-25292 medium pillow 1.8.0
CVE-2021-28678 medium pillow 1.8.0
CVE-2021-33430 medium numpy 1.8.0
CVE-2021-34141 medium numpy 1.8.0
CVE-2021-41496 medium numpy 1.8.0
CVE-2022-22815 medium pillow 1.8.0
CVE-2022-22816 medium pillow 1.8.0
CVE-2024-5206 medium scikit-learn 1.8.0
CVE-2025-61669 medium jupyter-server 2.17.0 1.8.0
CVE-2025-69873 medium ajv 6.12.6 1.8.0
CVE-2025-71176 medium pytest 1.8.0
CVE-2026-33532 medium yaml 2.8.2 1.8.0
CVE-2026-33750 medium brace-expansion 2.0.2 1.8.0
CVE-2026-39373 medium jwcrypto 1.5.6 1.8.0
CVE-2026-39377 medium nbconvert 7.17.0 1.8.0
CVE-2026-39378 medium nbconvert 7.17.0 1.8.0
CVE-2026-40260 medium pypdf 6.9.2 1.8.0
CVE-2026-41168 medium pypdf 6.9.2 1.8.0
CVE-2026-41205 medium mako 1.3.10 1.8.0
CVE-2026-41238 medium dompurify 3.3.2 1.8.0
CVE-2026-41239 medium dompurify 3.3.2 1.8.0
CVE-2026-41240 medium dompurify 3.3.2 1.8.0
CVE-2026-41305 medium postcss 8.5.6 1.8.0
CVE-2026-41312 medium pypdf 6.9.2 1.8.0
CVE-2026-41313 medium pypdf 6.9.2 1.8.0
CVE-2026-41314 medium pypdf 6.9.2 1.8.0
CVE-2026-41425 medium authlib 1.6.9 1.8.0
CVE-2026-41691 medium i18next-http-backend 3.0.2 1.8.0
CVE-2026-42034 medium axios 1.15.0 1.8.0
CVE-2026-42036 medium axios 1.15.0 1.8.0
CVE-2026-42037 medium axios 1.15.0 1.8.0
CVE-2026-42038 medium axios 1.15.0 1.8.0
CVE-2026-42039 medium axios 1.15.0 1.8.0
CVE-2026-42041 medium axios 1.15.0 1.8.0
CVE-2026-42042 medium axios 1.15.0 1.8.0
CVE-2026-42044 medium axios 1.15.0 1.8.0
CVE-2026-42308 medium pillow 1.8.0
CVE-2026-42309 medium pillow 1.8.0
CVE-2026-42310 medium pillow 1.8.0
GHSA-39q2-94rc-95cp medium dompurify 3.3.2 1.8.0
GHSA-jgpv-4h4c-xhw3 medium pillow 1.8.0
CVE-2026-41140 low poetry 2.3.3 1.8.0
CVE-2026-42040 low axios 1.15.0 1.8.0
GHSA-4fx9-vc88-q2xc low pillow 1.8.0
CVE-2020-13091 unknown pandas 1.8.0
CVE-2022-42969 unknown py 1.11.0 1.8.0
OSV-2022-1074 unknown pillow 1.8.0
OSV-2022-715 unknown pillow 1.8.0
PYSEC-2023-175 unknown pillow 1.8.0
PYSEC-2023-183 unknown opencv-python 1.8.0

Showing 181 of 181

Beta — feedback welcome: [email protected]